R0106-HP MSR Router Series Security Command Reference(V7)

84
If the source IP address of the packet is the IP address of a managed NAS, the server processes the
packet.
If the source IP address of the packet is not the IP address of a managed NAS, the server drops the
packet.
When you use both the nas-ip command and hwtacacs nas-ip command, the following guidelines
apply:
The setting configured by using the nas-ip command in HWTACACS scheme view is effective only
for the HWTACACS scheme.
The setting configured by using the hwtacacs nas-ip command in system view is effective for all
HWTACACS schemes.
The setting in HWTACACS scheme view takes precedence over the setting in system view.
If you execute the command multiple times, the most recent configuration takes effect.
Examples
# Set the source address for outgoing HWTACACS packets to 10.1.1.1 for HWTACACS scheme hwt1.
<Sysname> system-view
[Sysname] hwtacacs scheme hwt1
[Sysname-hwtacacs-hwt1] nas-ip 10.1.1.1
Related commands
hwtacacs nas-ip
primary accounting (HWTACACS scheme view)
Use primary accounting to specify the primary HWTACACS accounting server.
Use undo primary accounting to remove the configuration.
Syntax
primary accounting { ipv4-address | ipv6 ipv6-address } [ port-number | key { cipher | simple } string
| single-connection | vpn-instance vpn-instance-name ] *
undo primary accounting
Default
No primary HWTACACS accounting server is specified.
Views
HWTACACS scheme view
Predefined user roles
network-admin
Parameters
ipv4-address: Specifies an IPv4 address of the primary HWTACACS accounting server.
ipv6 ipv6-address: Specifies an IPv6 address of the primary HWTACACS accounting server.
port-number: Specifies the service port number of the primary HWTACACS accounting server. The value
range for the TCP port number is 1 to 65535, and the default setting is 49.
key { cipher | simple } string: Sets the shared key for secure communication with the primary
HWTACACS accounting server.